Client-side encryption of SQL columns using keys never revealed to the database engine, meaning cloud administrators and DBAs only ever see ciphertext.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Always Encrypted in context, with comparison tables and the common traps.
Terms in this definition
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA.
Related terms
- Column encryption key
In Always Encrypted, the key that actually encrypts column values; it sits encrypted in the database metadata and the driver retrieves it, so clients never receive it directly.
- Column-level encryption
Encrypting values one at a time using a database-held symmetric key and T-SQL functions such as
ENCRYPTBYKEY. Always Encrypted works differently: here, the app itself has to call T-SQL to encrypt and decrypt. - Column master key
Protects the column encryption keys in Always Encrypted. It never lives in the database itself but in Azure Key Vault or the Windows certificate store, and client apps need permission to use it.
- Deterministic encryption
Always Encrypted option where a given value always encrypts to identical ciphertext. That allows equality searches, joins, grouping and indexes, at the cost of exposing patterns in the data.
- image data type
A deprecated SQL Server type for large binary data, superseded by
varbinary(max). Columns of typeimagecannot be encrypted with Always Encrypted. - In-place encryption
A feature of Always Encrypted with secure enclaves: the server's enclave can encrypt, decrypt or re-encrypt a column (to rotate keys or switch encryption type) so the data never has to travel to the client.
- Intel SGX
Intel's hardware-based secure enclave technology. Always Encrypted relies on it for DC-series hardware in Azure SQL Database until it goes out of support at the end of October 2027 (31 October), after which VBS enclaves take over.
- Randomized encryption
Always Encrypted option where encrypting the same value gives new ciphertext every time. It is stronger than deterministic encryption, but the column can no longer be searched, grouped, joined or indexed.